@taurex said in Evaluating Open-source SIEM Solutions:
@notverypunny @scottalanmiller @JaredBusch thank you for your replies. We want to monitor databases, network devices, admin-level logins, etc. both on-prem and hosted for some suspicious activities or outages. I just thought that a SIEM would take care of the analytics/response part better than a monitoring solution like Elk, Greylog, OpenSearch, Zabbix, etc. which need a lot of fine-tuning to make them work in a similar fashion as a SIEM. We will check out Wazuh and compare it to SIEMmonster Community Edition, thanks.
SIEMs are often built on top of those.